ESPDS Scalable and Secure Infrastructure



Similar documents
VMware vsphere 5.1 Advanced Administration

VMware vsphere 5.0 Boot Camp

Content Distribution Management

System Requirements and Server Configuration

vsphere Private Cloud RAZR s Edge Virtualization and Private Cloud Administration

Vmware VSphere 6.0 Private Cloud Administration

EMC BACKUP-AS-A-SERVICE

STREAM FRBC

RSA Authentication Manager 8.1 Setup and Configuration Guide. Revision 2

VIDEO SURVEILLANCE WITH SURVEILLUS VMS AND EMC ISILON STORAGE ARRAYS

JOB ORIENTED VMWARE TRAINING INSTITUTE IN CHENNAI

VMWARE VSPHERE 5.0 WITH ESXI AND VCENTER

Requirement Priority Name Requirement Text Response Comment

White Paper. SAP NetWeaver Landscape Virtualization Management on VCE Vblock System 300 Family

VMware vcenter Log Insight Getting Started Guide

ACME Enterprises IT Infrastructure Assessment

Subject: Request for Information (RFI) Franchise Tax Board (FTB) Security Information and Event Management (SIEM) Project.

Managed Hosting is a managed service provided by MN.IT. It is structured to help customers meet:

OnCommand Performance Manager 1.1

Restricted Document. Pulsant Technical Specification

DISA Cloud: RACE (IaaS) and Platform as a Service (PaaS)

VirtualclientTechnology 2011 July

Remote PC Guide Series - Volume 1

NET ACCESS VOICE PRIVATE CLOUD

EMC Data Domain Management Center

Request for Proposal MDM Offeror s Questions for RFP for Virtual Private Network Solution (VPN)

Building the Virtual Information Infrastructure

VMware vsphere-6.0 Administration Training

Required Ports and Protocols. Communication Direction Protocol and Port Purpose Enterprise Controller Port 443, then Port Port 8005

Cloud Optimize Your IT

VBLOCK SOLUTION FOR SAP APPLICATION HIGH AVAILABILITY

Acronis Backup & Recovery 11.5

VMware vcenter Log Insight Security Guide

Virtual Private Servers

PolyServe Matrix Server for Linux

Unlimited Server 24/7/365 Support

EMC ViPR for On-Demand File Storage with EMC Syncplicity and EMC Isilon or EMC VNX

Whitepaper. Business Service monitoring approach

REDEFINE SIMPLICITY TOP REASONS: EMC VSPEX BLUE FOR VIRTUALIZED ENVIRONMENTS

OnCommand Performance Manager 1.1

VMware vsphere 4.1 with ESXi and vcenter

Host Hardening. Presented by. Douglas Couch & Nathan Heck Security Analysts for ITaP 1

Solicitation RFI-FTB-1415-SIEM Project. SIEM Project. Bid designation: Public. State of California

ZEN LOAD BALANCER EE v3.04 DATASHEET The Load Balancing made easy

ANS Monitoring as a Service. Customer requirements

Proof of Concept Guide

VCE Vision Intelligent Operations Version 2.5 Technical Overview

Future Multi-Mission Satellite Operations Centers Based on an Open System Architecture and Compatible Framework

vsphere Upgrade vsphere 6.0 EN

1 Data Center Infrastructure Remote Monitoring

Cisco Prime Data Center Network Manager Release 6.1

GRAVITYZONE HERE. Deployment Guide VLE Environment

Bosch Video Management System High Availability with Hyper-V

VMware vsphere: Install, Configure, Manage [V5.0]

McAfee Agent Handler

Hyper-V over SMB: Remote File Storage Support in Windows Server 2012 Hyper-V. Jose Barreto Principal Program Manager Microsoft Corporation

Hosted SharePoint: Questions every provider should answer

Introduction to VMware EVO: RAIL. White Paper

CHOOSE CONNECTRIA CLOUD AND MANAGED HOSTING

TPS Virtualization and Future Virtual Developments. Paul Hodge

Virtual Server and Storage Provisioning Service. Service Description

Cisco Application Networking Manager Version 2.0

MANAGEMENT AND ORCHESTRATION WORKFLOW AUTOMATION FOR VBLOCK INFRASTRUCTURE PLATFORMS

TEXAS AGRILIFE SERVER MANAGEMENT PROGRAM

VMware vcenter Log Insight Getting Started Guide

NexentaConnect for VMware Virtual SAN

VMware vsphere: [V5.5] Admin Training

Mobile Admin Architecture

Building Storage Service in a Private Cloud

SPEED your path to virtualization.

VMware Identity Manager Connector Installation and Configuration

Red Hat enterprise virtualization 3.0 feature comparison

PR03. High Availability

An Enterprise Backup Solution for GOES Operations Ground Equipment (OGE) and Spacecraft Support Ground System (SSGS)

Alliance Key Manager A Solution Brief for Technical Implementers

Cloud Service Assurance for Virtualized Multiservice Data Center

Network Configuration Manager

Brian LaGoe, Systems Administrator Benjamin Jellema, Systems Administrator Eastern Michigan University

Installing and Using the vnios Trial

SECURE, ENTERPRISE FILE SYNC AND SHARE WITH EMC SYNCPLICITY UTILIZING EMC ISILON, EMC ATMOS, AND EMC VNX

How To Install Vsphere On An Ecx 4 On A Hyperconverged Powerline On A Microsoft Vspheon Vsphee 4 On An Ubuntu Vspheron V2.2.5 On A Powerline

EMC DATA DOMAIN OPERATING SYSTEM

RED HAT ENTERPRISE VIRTUALIZATION

VMware vsphere Data Protection 6.0

WhatsUp Gold vs. Orion

SonicWALL WAN Acceleration FAQ Document

Logicalis Enterprise Cloud Frequently Asked Questions

shortcut Tap into learning NOW! Visit for a complete list of Short Cuts. Your Short Cut to Knowledge

McAfee Network Security Platform 8.2

ADVANCED NETWORK CONFIGURATION GUIDE

A Comparison of VMware and {Virtual Server}

The Incremental Advantage:

HP CloudSystem Enterprise

Enterprise IT is complex. Today, IT infrastructure spans the physical, the virtual and applications, and crosses public, private and hybrid clouds.

Part 1 - What s New in Hyper-V 2012 R2. Clive.Watson@Microsoft.com Datacenter Specialist

The best platform for building cloud infrastructures. Ralf von Gunten Sr. Systems Engineer VMware

[Document Title] SolarWinds Server & Application Monitor (SAM) [Document Subtitle] Angi Gahler. Share: Author: Manish Chacko

Virtual Managment Appliance Setup Guide

OnCommand Performance Manager 2.0

Index C, D. Background Intelligent Transfer Service (BITS), 174, 191

Transcription:

ESPDS Scalable and Secure Infrastructure Ensuring the NOAA/NESDIS Environmental Satellite Processing and Distribution Capabilities Meet the Growing User and Data Demands of Today and Tomorrow Rich Baker Solers, Inc. ESPDS Development Chief Architect 2013 AMS Annual Meeting

What is ESPDS? ESPDS: Environmental Satellite Processing and Distribution System Developed by the NESDIS Office of Systems Development (OSD), with Solers ( Team Solers ) as the development contractor Will be operated by the NESDIS Office of Satellite and Product Operations (OSPO) Modernizes the NESDIS Environmental Satellite Processing Center (ESPC) Single enterprise solution that meets the needs of existing (legacy), Suomi NPP, JPSS, and GOES-R, with scalability to meet future environmental satellite needs No more stovepipes! Includes modernization of the Ingest, Product Generation (PG), Product Distribution (PD), and Infrastructure segments of the ESPC Provides environmental satellite data and services to a growing user community including: NOAA Line Offices (NWS, NMFS, NOS, NIC, NESDIS, etc.) DoD (AFWA, NAVO, etc.) Other U.S. and international users (government agencies, universities, foreign partners, etc.) Will be implemented at the primary and backup ESPC sites: Primary ESPC site is the NOAA Satellite Operations Facility (NSOF) in Suitland, MD Future ESPC backup site is the Consolidated Back-Up (CBU) facility in Fairmont, WV Provides a scalable and secure infrastructure as a foundational building block upon which all other system functions reside 2

Traits of a Scalable Infrastructure No Single Point of Failure Redundancy and fault tolerance as key design tenants throughout Line Replaceable Units Can upgrade or replace existing hardware and software components without impacting operational availability Business Process Flexibility and Extensibility Can change existing business processes within the system, and integrate new business processes into the system, without impacting operational availability Horizontal Scalability Can add additional hardware resources (computing, network, storage) and software business processing instances without impacting operational availability 3

Traits of a Secure Infrastructure Complies with applicable IT security policies, procedures, and controls: NIST SP 800-53 DOC/NOAA IT Security Handbook Center for Internet Security (CIS) Benchmarks DISA STIG Etc. Provides a defense-in-depth foundation for securing the system that includes: Network security Centralized identity/account management, authentication, and authorization Host-based intrusion detection and prevention Anti-malware Integrated monitoring, logging, and reporting (Security Incident and Event Management [SIEM]) 4

ESPDS Scalable and Secure Infrastructure Suomi NPP and JPSS (via IDPS) GOES-R GS PD Non-NOAA Satellites (MSG, MTSAT, INSAT) Ancillary Data Providers Legacy GOES Legacy POES Future Missions Satellite Ingest Computing Cluster Scalable x86 hardware cluster with specialized adapters to interface with satellite antenna systems and perform RF/IF to IP conversion of the data Resource Management Communications Framework Logging & Reporting Monitoring Product Generation Computing Cluster Scalable x86 hardware cluster that leverages a grid computing scheduler to perform PG algorithm execution and report applicable status/metrics Common Infrastructure Services Identity/Account Management HIDS Anti-Malware/HIPS Network Management Converged 10Gb IP Networking Virtualized Computing Cluster Scalable x86 hardware cluster that hosts the distribution and access, PG management, common infrastructure, and other services as Virtual Machines (VMs) Database Data Intake & Transmission Scheduling System Backup Enterprise Shared Storage Scale-Out Enterprise Network Network Attached Attached Storage Storage (NAS) (NAS) solution solution with with standard standard IP-based IP-based file file access access protocols protocols (NFS, (NFS, CIFS, CIFS, HTTP, HTTP, FTP) FTP) (EMC Isilon) Includes switches, firewalls, and Network IDS components (Cisco) NOAA Line Offices DoD CLASS Other U.S. and International Users Ancillary Data Users (PG Systems) 5

Common Infrastructure Services The following slides provide an overview of the Common Infrastructure Services depicted in the previous diagram Resource Management Communications Framework Logging & Reporting Monitoring Identity/Account Management HIDS Anti-Malware/HIPS Network Management Database Data Intake & Transmission Scheduling System Backup 6

Resource Management VMware vsphere/esxi, vcenter, and Orchestrator 7

Communications Framework User /Operator/ Admin HTTPS (S)FTP(S) Load Balancer (S)FTP(S) Client (S)FTP(S) VM (S)FTP(S) Server GOES-R GS PD WS Client Other System WS Client ESPDS SOAP over HTTP HTTPS Portal Portal (S)FTP(S) (S)FTP(S) (S)FTP(S) Server Server (S)FTP(S) Other Other (S)FTP(S) PDA Client Client Service ESPDS Service Load Balancer SOAP over HTTPS VM SOAP over HTTP(S) ESB ESB SOAP over JMS 1.1 JMS Broker VM SOAP over JMS 1.1 JMS Broker VM SOAP over JMS 1.1 Application Server ESPDS Service VM Application Server ESPDS Service VM Application Server ESPDS Service VM WSO2 ESB and Application Server Apache ActiveMQ Java Message Service (JMS) Broker Red Hat Linux Virtual Server (LVS) Load Balancer 8

Logging & Reporting Windows Event logs (WMI) Microsoft Windows Layer 3 Switch (Cisco) Firmware logs (Syslog) Monitoring (SolarWinds Orion) Directory Server (Microsoft Active Directory) vcenter, ESXi, Resource Coordinator, Red Hat Repository logs (WMI) Resource Management (VMware vcenter) Computing HW (Cisco UCS) Firmware logs (Syslog) SolarWinds Orion logs (WMI) Windows Event logs (WMI) Apache SSHD/FTPD logs (Rsyslog) Data Intake/Data Transmit ([S]FTP[S] Server/Client) NAS Storage (Isilon) SAN Storage (EMC VNX) Firmware logs (Syslog) Firmware logs (Syslog) Linux OS logs (Rsyslog) Red Hat Enterprise Linux Administrator Portal Logging & Reporting (Tripwire Log Center) Web server logs (Rsyslog) User Portal Custom Java Service logs (Rsyslog) Other Java Components (e.g. Subscription, Product Tailoring, Ad- Hoc search) WSO2 ESB, WSO2 AS, Red Hat LVS logs (Rsyslog) Oracle logs (Rsyslog) Communications Framework (WSO2, ActiveMQ, Red Hat LVS) Database (Oracle RDBMS) Tripwire Log Center Rsyslog (Linux-based syslog client) Windows Management Interface (WMI) 9

Monitoring Microsoft Windows resource and service status (WMI) Microsoft Windows Layer 3 Switch (Cisco) Computing HW (Cisco UCS) SAN Storage (EMC VNX) NAS Storage (EMC Isilon) Interface Status and Bandwidth Usage (SNMP) Blade Resource Utilization (SNMP) I/O Data and Storage Usage (SNMP) I/O Data and Storage Usage (SSH) Red Hat OS resource and service status (SNMP) Red Hat Enterprise Linux Administrator Portal Logging and Reporting (Tripwire Log Center) Service/Process Status and Resource Allocation (SSH/RMI) Directory Server (Microsoft Active Directory) Monitoring (SolarWinds Orion) User Statistics (SSH) User Portal Web Interface Authentication (LDAPS) Service/Process Status and Resource Allocation (SSH/RMI) VM CPU, Memory, and Network performance measurements (SNMP) Other Java Components (e.g., Subscription, Product Tailoring, Ad- Hoc search) Connection Status and Transfer Rate (SNMP) Service/Process Status and Resource Allocation (SSH/RMI) Service/Process Status and Resource Allocation (SSH/RMI) Resource Management (VMware vcenter) Data Intake/Data Transmit ([S]FTP[S] Server/Client) Comm Framework (WSO2, Red Hat LVS) Data Management (Oracle RDBMS) SolarWinds Orion Network Performance Monitor (NPM) and Application Performance Monitor (APM) Red Hat Simple Network Management Protocol (SNMP) Agent and Secure Shell (SSH) Server Windows Management Interface (WMI) 10

Identity/Account Management Centralized identity and account management solution Manages human user accounts (internal and external users, operators, administrators) Manages machine and operating system accounts Provides Kerberos and web services-based authentication and authorization services Compatible with NOAA/NESDIS HSPD-12 solution (DoD CAC PIV token, X509 PKI certificates) Microsoft Active Directory Centrify ForgeRock OpenAM 11

HIDS Centralized Host-based Intrusion Detection System (HIDS) solution Ensures integrity of critical system and configuration files across the infrastructure, including: Computing device firmware Networking device firmware Storage device firmware Operating systems Applications and services Tripwire Enterprise 12

Anti-Malware/HIPS Provides virus scanning and Host-based Intrusion Prevention System (HIPS) capabilities across all machines and operating systems Centralized virus signature and HIPS policy management (automated deployments and updates) McAfee VirusScan Enterprise, HIPS, and epolicy Orchestrator 13

Network Management Domain Name Service (DNS) Server Dynamic Host Configuration Protocol (DHCP) Server Network Time Protocol (NTP) Server Microsoft Windows DNS and Time Services (integrated with Active Directory) Red Hat DCHP Server Red Hat NTP Server 14

Database Highly Available Relational Database Solution Two Oracle Database 11gR2 Enterprise Edition Database Server instances One primary instance providing client access One identical standby instance to receive/apply redo operations from primary database Oracle Data Guard configuration established between primary & standby database servers to maintain duplicate copy of operational database Supports high database availability and fast start failover Oracle Database 11gR2 Enterprise Edition with Data Guard Hibernate (database client access) 15

Data Intake & Transmission FTP, FTPS, and SFTP client and server solutions Used to obtain product and ancillary data from providers (intake), and deliver product and ancillary data to consumers (transmission) via push or pull Apache FtpServer (FTP and FTPS Server) Apache SSHD (SFTP Server) Apache Commons Library (FTP, FTPS, and SFTP Client) 16

Scheduling Schedules periodic operations to be performed within the infrastructure Product and ancillary data inventory cleanup (expired files) Subscription-specific product and ancillary data acquisition Extensible to accommodate future scheduling needs Terracotta Quartz Scheduler 17

System Backup Performs periodic backup of specific system data and files to support on-site archive and recovery Backups include: VM image files Database contents Log files Configuration files EMC NetWorker 18

ESPDS Scalable and Secure Infrastructure Benefits To End Users Ensures highly available and reliable access to human and machine interfaces that scales to accommodate the growing user and data demands Provides flexibility to quickly adapt to changes in end user requirements To System Operators/Administrators Easily scalable hardware and software Provides automated operations Compliant with IT security requirements for a High Impact system To NOAA/NESDIS As A Whole Scalable and secure foundation to support enterprise environmental satellite services across NOAA/NESDIS Removes mission-specific stovepiping Paving the path toward modernized data centers 19

Questions 20